Senior Security Assurance Analyst
SWBC is seeking a talented individual who will protect the organization, its clients, and its business operations through risk-based security assessments, third-party security reviews, control validation, and assurance activities. This role serves as a trusted advisor to technology, business, compliance, procurement, and security stakeholders, helping them understand and manage cybersecurity risk while supporting regulatory, contractual, and business requirements. As a key member of the Security team, you will perform in-depth security assessments, evaluate vendor security programs, review security controls, analyze evidence, and develop clear, actionable recommendations that strengthen the organization's security posture. If you enjoy solving complex problems, conducting investigative analysis, working with a wide variety of stakeholders, and translating technical risks into practical business guidance, this role may be a great fit for you.
Why you'll love this role:
In this role, your work will directly influence business decisions, technology investments, third-party partnerships, and enterprise risk management efforts across the organization. You'll have the opportunity to work with executives, business leaders, technology teams, legal professionals, auditors, and industry partners while helping drive a mature and risk-focused security program. You'll join a collaborative security team that values professional growth, continuous improvement, critical thinking, and practical problem-solving. Every assessment, review, and recommendation you deliver will contribute to protecting the business while enabling innovation and operational success.
Essential duties include the following:
- Perform security assessments of applications, systems, cloud services, technology platforms, business processes, and third-party solutions.
- Evaluate security controls and identify potential risks, control gaps, and improvement opportunities.
- Develop practical, risk-based recommendations that help stakeholders make informed business decisions.
- Document findings, conclusions, and risk decisions in a clear and professional manner.
- Review vendor security questionnaires, SOC reports, certifications, penetration testing reports, and supporting security documentation.
- Assess the security capabilities of prospective and existing third-party service providers.
- Partner with Procurement, Legal, business teams, and vendors to resolve security concerns and document residual risk.
- Assist with internal audits, external audits, client assurance requests, and regulatory examinations.
- Review evidence supporting security controls and evaluate control effectiveness.
- Help ensure documentation remains accurate, complete, traceable, and audit-ready.
- Produce executive-ready assessment summaries, risk narratives, and remediation recommendations.
- Present findings to technical and non-technical audiences.
- Support reporting on assessment activity, emerging risks, remediation efforts, and security trends.
- Work closely with Security, Technology, Compliance, Legal, Procurement, and business stakeholders.
- Help teams understand security requirements, control expectations, and business risks.
- Contribute to the ongoing enhancement of security assessment processes, templates, standards, and reporting practices.
Serious candidates will possess the minimum qualifications:
- Bachelor's degree in Cybersecurity, Information Security, Information Systems, Risk Management, Audit, Computer Science, or a related field, or equivalent experience.
- Minimum of five (5) years of experience in cybersecurity, IT risk, IT audit, compliance, third-party risk management, security assessments, or related discipline.
- Experience conducting independent security assessments and documenting risk-based findings.
- Experience reviewing security controls, vendor documentation, SOC reports, audit artifacts, remediation plans, and compliance evidence.
- Experience working with enterprise technology environments, cloud platforms, and third-party service providers.
- At least one of the following certifications is required, others are strongly preferred: CISSP, CISA, CRISC, GIAC certifications
- Other relevant cybersecurity, risk, audit, or assurance certifications
- Experience performing vendor risk assessments or third-party security reviews.
- Experience supporting audits, examinations, or client assurance activities.
- Familiarity with cloud security, application security, identity and access management, or data protection controls.
- Experience using GRC, workflow, ticketing, or evidence management platforms.
SWBC offers*:
- Competitive overall compensation package
- Work/Life balance
- Employee engagement activities and recognition awards
- Years of Service awards
- Career enhancement and growth opportunities
- Leadership Academy and Mentor Program
- Continuing education and career certifications
- Variety of healthcare coverage options
- Traditional and Roth 401(k) retirement plans
- Lucrative Wellness Program
*Based upon employee eligibility
Additional Information:
SWBC is a Substance-Free Workplace and requires pre-employment drug testing.
Please note, SWBC does not hire tobacco users as allowed by law.
To learn more about SWBC, visit our website at www.SWBC.com. If interested, please click the appropriate apply button.